Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-FRAME-OPTIONS
X-Request-ID
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
Server-Timing
X-AspNetMvc-Version
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Backend
X-Robots-Tag
X-Cache-Group
Cf-Edge-Cache
Host-Header
Keep-Alive
X-UA-Device
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Server-Powered-By
Allow
X-Age
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
P3p
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
Cf-Railgun
X-Device
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-CacheTime
X-Swift-SaveTime
Accept-CH
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
Surrogate-Control
X-CST
X-Nginx-Cache-Status
X-Readtime
X-Cache-Lookup
X-Akam-SW-Version
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
X-Trace
X-Response-Time
X-Edge
Accept-CH-Lifetime
X-HW
Accept-Ch-Lifetime
X-Ua-Compatible
Content-Location
X-Clacks-Overhead
X-Mod-Pagespeed
X-Midtier
X-Oneagent-Js-Injection
X-ECACHE
X-Url
Rating
X-ESI
Xkey
X-Amz-Server-Side-Encryption
X-Mcache
X-Ruxit-JS-Agent
X-Country
X-Ruxit-Js-Agent
X-Upstream
X-Litespeed-Cache
X-Vcap-Request-Id
X-Vname
X-TtlSet
X-PC
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Rack-Cache
Verso
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Element-Page-Cache
X-Kinja
X-Exp-Variant
Edge-Control
RTSS
X-Cache-TTL
X-Powered-By-Plesk
Fastly-Restarts
Origin-Trial
X-VARITI-CCR
X-Ac
X-Navigation-Version
X-Abt-Application-Version
Service-Worker-Allowed
X-Cached
X-Goog-Hash
Accept-Ch
X-Country-Code
X-Content-Type
X-Ttl
X-GitHub-Request-Id
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Amz-Rid
X-Browser-Type
X-Dw-Request-Base-Id
X-Mg-S
X-WebKit-CSP-Report-Only
X-SharePointHealthScore
SPRequestGuid
Cross-Origin-Opener-Policy
X-Server-Name
X-Varnish-TTL
Arr-Disable-Session-Affinity
X-Instrumentation
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Amzn-Trace-Id
X-Powered-CMS
X-Middleton-Response
Response
X-Webkit-CSP
AR-Request-ID
AR-ATIME
AR-SID
AR-PoweredBy
SPRequestDuration
SPIisLatency
X-Cache-Key
X-B3-TraceId
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Version
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Accel-Expires
X-Cnection
X-B3-Traceid
Cache-Tags
X-T
Cache-Status
X-Client-IP
Front-End-Https
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Times
X-MSEdge-Ref
Edge-Cache-Tag
X-Fastcgi-Cache
X-Px
Nginx-Cache
X-NWS-LOG-UUID
X-Hits
X-Ser
X-Kinja-CCPA
X-NF-Request-ID
Public-Key-Pins
MRF-Tech
X-B3-TraceId-Primal
X-Recruiting
Mrf-Cache-Status
X-LLID
X-Request-Received
X-Frontend
X-Request-Processing-Time
Payment
Server-Node
X-Ua-Browser
X-Shield-Request-Id
X-Webkit-CSP-Report-Only
X-Erf-Stays-Pdp-Viaduct-Migration-Web
X-RateLimit-Remaining
X-DIS-Request-ID
Access-Control-Request-Method
TP-Cache
X-FastCGI-Cache
S
MicrosoftSharePointTeamServices
X-Goog-Metageneration
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-LB-Cache
TP-L2-Cache
X-PressLabs-Stats
X-RateLimit-Limit
X-Ratelimit-Remaining
X-Content-Digest
Content-MD5
X-Distributor
X-Request-Handler-Origin-Region
X-Microsite
Realpath
X-Ezoic-Cdn
X-Forwarded-For
X-Geo-Country
X-FB-Debug
X-Page-Id
Access-Control-Allow-Method
X-Hostname
Accept-Charset
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cluster-Name
X-GUploader-UploadID
X-Protected-By
Fastcgi-Cache
X-Rid
X-Server-ID
X-Seen-By
X-B3-Sampled
X-Envoy-Decorator-Operation
X-Ratelimit-Limit
Cleartype
TCN
X-Correlation-Id
DC
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
Referer-Policy
X-Goog-Stored-Content-Length
X-Newrelic-App-Data
X-TEC-API-ORIGIN
X-Mobile
X-TEC-API-VERSION
X-TEC-API-ROOT
Cross-Origin-Resource-Policy
X-Origin-Server
X-Origin-Cache
X-Debug-Info
X-Varnish-Backend
X-Logged-In
X-Git-Hash
X-XRDS-Location
X-Webkit-Csp
X-Content-Options
X-Azure-Ref
X-Varnish-Grace
X-Contextid
Count-Hit
X-Grace
X-Aspnet-Version
X-Is-Crawler
X-Flags
X-Fb-Rlafr
X-Amz-Replication-Status
X-App-Environment
X-Aspnet-Duration-Ms
X-Providence-Cookie
Surrogate-Key
X-Request-Guid
X-Route-Name
X-TTL
X-Revision
X-Edge-Location-Klb
X-Ua-Device
X-IPS-LoggedIn
X-Kinsta-Cache
X-TT
X-Amz-Meta-S3cmd-Attrs
Alternate-Protocol
X-App-Server
Healthy
X-Hosted-By
X-Forwarded-Proto
X-Wix-Request-Id
Frame-Options
X-Whom
WPO-Cache-Message
WPO-Cache-Status
X-Daa-Tunnel
Charset
MS-Author-Via
X-Akamai-Edgescape
Viewport
Retry-After
X-Magnolia-Registration
X-Id
Filterid
X-F-Cache
Paypal-Debug-Id
X-Backend-Name
Section-Io-Cache
X-B
SRV
X-Aspnetmvc-Version
X-Cache-Age
X-Client-Ip
X-Activity-Id
X-AppVersion
X-Az
X-Proxy-Cache-Info
Amp-Access-Control-Allow-Source-Origin
X-Nf-Request-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Time
X-Trace-Id
X-Www-Served-By
X-App-Version
X-Cache-Control
X-RateLimit-Reset
Server-Name
X-Type
X-Varnish-Server
Host
X-Instance
X-Original-Request-Id
X-Response-Served-From
X-ARC
X-Cache-Rule
Akamai-GRN
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Rule
X-Http-Reason
X-Rocket-Nginx-Serving-Static
X-UUID
X-Edge-Location
X-Proxy
X-Varnish-Age
X-EdgeConnect-Cache-Status
X-Cache-Grace
X-N
X-Status
Protected
Front
X-Akamai-Request-ID2
X-User-Agent
X-FW-Static
From-Origin
X-FW-Version
Fastly-SWR
X-FW-Server
Fastly-SIE
X-FW-Dynamic
X-Is-Bot
X-Cacheable-TTL
X-Environment-Context
X-Framework
X-FW-Hash
X-FW-Serve
X-FW-Type
X-Page-View
X-Region
X-Rendered-As
Refresh
X-Jobs
X-Unique-Id
X-L-Path
X-Adobe-Loc
X-Adobe-Content
Access-Control-Request-Headers
X-Oracle-Dms-Ecid
X-Cache-Time
X-Load-Cache
X-Language
X-Tumblr-Pixel
X-Oracle-Dms-Rid
X-Tumblr-Pixel-0
X-Tumblr-User
X-ProcessESI
X-G
X-RemovedCookies
X-Tumblr-Pixel-1
Version
ServerID
X-COUNTRY
Country
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-CDN-Forward
X-Source
Content-Disposition
X-Drupal-Cache-Tags
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Vcache
X-Varnish-Ttl
X-Mg-Request-UUID
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
Accept-Language
X-Debug-IsConnected
X-HTML-Minification-Powered-By
X-Debug-IsPreview
Countrycode
X-Upgrade-Enabled
X-DynaTrace
X-DataDome
X-B-Cache
Xet-Cookie
X-Signature
X-Tt-Trace-Host
Backend
X-Tt-Trace-Tag
X-Generated-By
CF-IPCountry
X-ID
X-DynaTrace-JS-Agent
Webserver
X-Xrds-Location
X-Nginx-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Xserver
X-ECache
X-Mode
X-Httpd
X-Servername
Liferay-Portal
Url
X-Tec-Api-Root
X-Tec-Api-Origin
X-Device-Type
X-NYM-Debug-Backend
X-Tec-Api-Version
X-Tt-Logid
X-Content-Age
X-Content-Powered-By
GEO-INFO
X-Zen-Fury
X-Erf-Web-Scheduler
X-Drupal-Cache-Contexts
X-Container-Uri
X-ServerID
X-Cache-Action
Fastcgi-Useragent
X-SayCDN-TTL
Filters
X-UPSTREAM-Address
X-Tb
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-SlotName
X-GeoCode
X-Storage
X-Director
X-Say-TTL
X-Say-Cacheable
S-Rt
X-SaId
X-LAGOON
X-GeoCountry
Onion-Location
Meta-Geo
Locale
X-Proto
X-Rewrite-Enabled
X-Cache-Operation
Azure-InstanceId
X-Urbn-Site-Id
X-Git-Commit
X-Varnish-Cache-Hits
X-JoinUs
X-Urbn-Context-Path
Load-Balancing
X-Cluster-Node
X-PHP-Host
X-Forwarded-Host
X-Labrador-Cache-Channel
X-VC-Cache
X-Soup
X-RM-Cache-TTL
X-Varnish-Hostname
Uber-Trace-Id
X-XRDS-LOCATION
X-Ms-Request-Id
X-Ms-Version
X-Generation-Time
X-Served-From
X-Detected-As
X-B3-SpanId
Web-Mar-Node
X-Adobe-Source
X-Cache-Server
X-Sql-Count
X-Logging-Id
X-VCT
X-Sucuri-ID
X-Sucuri-Cache
X-Sql-Duration-Ms
TWC-Device-Class
X-Skip-Cache
X-Extlb
Webcakes-Region
X-Debug
Webcakes-App-Version
DB-Nickname
TWC-Privacy
X-Zipkin-Id
Webcakes-App-Name
X-FB-TRIP-ID
TWC-Connection-Speed
X-Proxied
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Routing-Service
X-Origin-Hint
Property-Id
TWC-Locale-Group
Mn-Server-Ip
Node
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Lambda-Id
Selected-Fe
X-Tumblr-Pixel-3
X-LSADC-Cache
X-Timing-Wait
X-Tumblr-Pixel-2
X-Format
X-Fetched-On
X-Uri
X-Proxy-Build
X-Template
OT-Force-Account-Verify
Fastly-Drupal-HTML
Source
CDN-RequestId
X-Ratelimit-Reset
X-Origin-Date
X-Srv
X-MP-GENERATED-AT
X-Tncms
X-Loop
X-Cache-Hit
X-URL
X-Pass-Why
X-Endurance-Cache-Level
X-Varnish-Hits
X-MCACHE
X-Cache-Expired-At
X-TimeS
X-Redis-Cache
X-Ua
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
Content-Secure-Policy
X-Real-IP
X-Cache-TTL-Remaining
X-UA-Device-Type
Section-Io-Origin-Time-Seconds
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
Section-Origin-Responded
X-CCDN-Origin-Time
Section-Io-Origin-Status
Section-Io-Id
X-Origin-CC
X-Origin-TTL
X-Pubstack
X-AIR-PT
X-Rn-Rsrv
X-Fastly-Request-Id
X-Via-JSL
X-NGENIX-Cache
X-Server-W
X-S
X-Node-Name
X-Datadome
X-Newrelic-Synthetics
MS-CV
Ms-Operation-Id
X-RTag
X-GEO
X-CSRF-Token
Cache-Provider
NGB
Cache-Hits
CDN-Uid
CDN-EdgeStorageId
CDN-Cache
CDN-PullZone
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-CachedAt
CDN-RequestPullSuccess
X-Cache-Host
X-Hl-Ver
X-Akamai-Transformed
Cache-Name
X-Restarts
X-Reqid
X-IPLB-Instance
X-Cms-Context
X-Cache-Type
X-Xfnlog-Site
Apigw-Requestid
X-Optimistic-Header
X-IPLB-Request-ID
X-PHP-Backend
X-No-Session
X-ProxyCache-Status
X-Parent-Response-Time
X-BYPASS-REASON
X-Handled-By
X-ProxyCache-Key
X-A-Dcw
X-A-Dam
X-Accel-Buffering
Xc-Version
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dgt
X-Policy
X-Nyt-Route
W
VNS-Cache
We-Hiring
VNS-Age
X-A
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-A-Ccd
Rendered-Blocks
Fastly-SSL
Fastly-GeoIP-CountryCode
Gannett-Cam-Experience-Id
Gh-Request-Id
HA-Ipaddr
Ha-Gx-Prefs
Fastly-Backend-Name
DCR-Processing-Time-Ms
Candidate-Md5Url
Canary
CPC-Age
CPC-Cache
DCR-Decision-By
L
L5d-Success-Class
Redirect-Candidate
Odigeo-Trace-Id
Server-Host
Sslversion
T-Server
Surrogated-Key
Ngx.Var.Host
N-Cache
Magicmarker
Lang
Mail-Subject
MD5-Digest
Meta-Geo-Continent
X-JWT-State
X-Cache-NE
X-SRCache-Key
X-Dispatcher-Number
X-Developer
X-Origin-Time
X-Has-Esi
X-Ec-Custom-Error
X-Slack-Shared-Secret-Outcome
X-Tenant
BehaviorPad-Version
X-Debug-Cache-Fetch
X-Date
X-Debug-Cache-Store
X-Is-Gdpr
X-Destination
X-Var-Ttl
X-Ec-Fail
X-Ec-GeoHdr
X-Gdpr
X-Forwarded-Path
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-ScT
X-Orig-Expires
X-FC-Vary-Parameters
X-Shop-Environment
X-Epic-Correlation-Id
X-S-Cookie
X-Eu-Site
X-External-Request-Id
X-Slack-Backend
X-Fastly-Backend
X-Vdms-Path
X-D
X-RateLimit-Remaining-Second
X-Cache-Bucket
X-Cache-Info
X-Wikidot-Static-Cache
X-CacheTTL
X-Request-Host
X-Bl-Debug
X-BCube-Filmed-By
X-App
X-Worker
X-Application
X-B-Cookie
X-Bc-Bl
X-Wix-Viewer-Type
X-Cdn-Diag
X-Mvc-Supplant-Cachable
X-RateLimit-Limit-Second
X-Vdms-Version
X-CF-Lambda-Version
X-CGP
X-Csrf-Jwt
X-Conf
X-VG-WebCache
X-Rojux
X-CF-Lambda-Fn
X-SD-PageType
X-Wikidot-Backend
X-We-Are-Hiring
X-Viewer-Country
X-Vtex-Remote-Cache
X-Aed
Web-Mar-Region
X-CACHE-AGE
X-Correlation-ID
X-LJ-Flow-ID
X-AWS-Id
ServedBy
X-VWS-Id
X-Cluster
X-Owner
X-PAYTM-SRV-ID
X-Geo-Header
X-Pool
X-PERF
X-Org
X-App-Name
X-Auto-Login
X-ApacheServer
X-Alternate-Cache-Key
X-Access
X-Qloud-Router
X-Origin-Response-Time
Thinkindot-CacheControl-Type
Req-Svc-Chain
X-ShopId
X-Shopify-Stage
Release
Producers
X-Sn-Servicetimems
X-ShardId
X-Server-IP
X-Old-Content-Length
Thinkindot-Control
Thinkindot-CacheControl
TDXMobile
X-S-Maxage
X-Request-Time
X-Cache-Debug
X-Irp-Debug
X-DPWN-IS-SECURE
X-DefHash
X-DefElseHash
X-Core-Value
X-Level-Front-Cache
X-INCAP-ABP
X-Human
X-Fmm-Version
X-Generated-On
X-Gzip
X-Hash
X-Esi-Check
X-Core-Mission
X-Loc
X-Cache-Id
X-Nitro-Cache
X-Node-Id
Platform
X-Bip
X-Mly-Id
X-Cdn-Origin
X-CMSURLCustom
X-Section
X-Clientip
X-Clara-WADP
X-Mid
X-BBC-Edge-Cache-Status
X-Platform
Machine
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Cmstype
X-Varnish-CookieHashed-On
X-Variation
AKAMAI
X-Thinkindot-L3
Memcached
X-Up
X-Varnishpool
Is-Eu
X-VServer
Cmsid
Datacenter
X-WADP-Cache
X-Vmg-Version
Environment
Host-ID
X-VG-TLSProxy
Expect-Staple
X-Thanos
Adler-Geo
Origin
X-Test
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Tx-Id
X-Proxy-Cache-Status
User-Cache-Control
Apple-News-Services-Request-Url
X-Forwarded-Site
X-Cdn-Srv
X-Origin
NM-Fastcgi-Cache
X-Device-Os
X-Akamai-Device-Characteristics
X-GeoIP
X-Nananana
Esi-Enabled
CloudFront-Viewer-Country
X-Nginx-Cache-Key
X-NodeID
X-Block-Status
Apple-News-Services-Host
X-Gen-Mode
X-Mvc-Supplant-OutputCached
CDCHOST
X-Dispatcher-Server
X-Hnp-Log
X-From
X-WA-Info
Server-Hostname
Sever-Int
Server-Ext
Apple-News-Services-Parsed-Url
DSUID
Apple-News-Services-Handled
X-Scale
Country-Code
X-Via-Fastly
Server-Info
X-Vcl-Version
X-Refresh
X-Cache-Enabled
Ssr
X-TIM-N
Pics-Label
Origin-EX
X-TA-CDN-Provider
Wxu-Next-Region
WP-Super-Cache
Wxu-Next-Commit
Wxu-Next-Hostname
Origin-CC
X-LB-NoCache
X-Instance-Name
X-NCache
X-Op-Id-All
C-Via
X-Presslabs-Stats
X-Cs
X-Cache-Status-Check
X-Air-Source
X-Amz-Meta-Cb-Modifiedtime
X-Air-Trace-Id
Server-ID
Hostname
Time
X-Air-Hostname
Memory
X-TIME
X-API-Version
AMP-Access-Control-Allow-Source-Origin
X-HA-Backend
Origin-Agent-Cluster
X-ZONE
Cf-Device-Type
X-Web-Node
X-Dc
X-Azure-Ref-OriginShield
NGX
GeoIP-Latitude
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Beresp-Grace
X-VHOST
X-Varnish-Beresp-Ttl
X-Platform-Processor
X-Origin-Expires
X-Microcachable
X-Platform-Cluster
X-CACHE-GROUP
X-Platform-Router
Cache-Host
Cdn-Requestid
X-B3-Spanid
X-Micro-Cache
X-Internal-Host
XM
X-Vgn-Hpd-Reason
X-Fpc
X-Wp-Cf-Super-Cache-Active
PFcat
X-HN
YJS-ID
X-Site-Version
X-DC
X-Locale
X-VarnishDD-TTL
X-Webkit-Csp-Report-Only
Resin-Trace
X-AB
X-Ad-Defer-Variation
X-TraceId
X-LiteSpeed-Cache-Control
X-WP-CF-Super-Cache-Active
X-Via-CDN
X-Via-Edge
X-Via-SSL
Sid
X-FL-EDGE
Locid
Edge-Copy-Time
X-FL-QIT-DEBUG
A
Srvid
Location
X-Zone
X-Geo-Region
X-Buckets
IsBot
True-Client-Ip
X-Github-Request-Id
Uri
X-B3-Parentspanid
X-FTR-Request-ID
X-Pod-Name
X-SIPLIST1
X-Accel-Version
X-Cache-ASPX
X-ATG-Version
GeoIP-Country-Code
X-Moov-Xdn-Version
X-Moov-T
X-Cached-By
User-Agent
X-DataCenter
X-FireWall-Port
X-Contensis-Viewer-Groups
X-Backend-Instance
X-Upstream-Ht
X-Upstream-Ct
X-Info
X-Varnish-Authentication
Cache-Key
X-Is-Mobile
X-Is-Tablet
X-Is-Desktop
X-Browser-Name
X-VCache
X-Tcp-Rtt
X-Is-Supported-Browser
CF-Ctrl
Cdn
X-NGINX-Cache
X-Datacenter
X-Nitro-Cache-From
X-Nitro-Rev
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
NtCoent-Length
GeoIp-Country-Code
State
X-MSEdge-Flight
X-Platform-Server
X-Planisys-CDN-Cache
X-MSEdge-Features
X-HS-Content-Campaign-Id
X-VC
Lb
X-LiteSpeed-Tag
SID
X-Geo
XServer
X-Release
Epwk-X-Cache
X-Hyper-Cache
X-CS
X-Provided-By
X-Fastly-Cache
X-NewRelic-App-Data
X-CSRF-TOKEN
True-Client-IP
X-Rocket-Build-Number
Path
X-Sigma
X-Sigma-Backend
X-Cache-Remote
X-RN-RSRV
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-TRACE-ID
X-Vgn-Hpd-Cached
X-Service
Cache
X-Frame-Option
X-HS-Status
X-Webstats-RespID
X-Scheme
X-Generated-In
X-Gamma-Serve
X-GeoIP-City
X-FPC
X-Api-Version
Fastly-Drupal-Html
Tcn
X-HostName
X-SRV
X-Pad
X-GoCache-CacheStatus
X-Rebelmouse-Cache-Control
Cf-Ipcountry
CountryCode
X-Origin-Cache-Key
X-UA
Serverid
X-Rebelmouse-Surrogate-Control
X-APP-VERSION
Cdn-Request-Time
Cdnsip
X-Air-Pt
Cdncip
X-Edge-Server
Ohc-File-Size
X-Vercel-Id
X-Amz-Meta-Opti
X-Vercel-Cache
X-Esi
X-AK-Request-ID
Cdn-Host
X-Guploader-Uploadid
Cache-Tv-Group
X-Branch-Name
X-Wp-Cf-Super-Cache-Cache-Control
WebServer
X-Cache-Ttl
M-TraceId
X-Wp-Cf-Super-Cache
Req-ID
X-FTR-Balancer
Kp-EeAlive
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-EC-Lua
X-NMSegId
X-FTR-Expires
X-FTR-Cache-Status
X-Traceid
X-Cdn-Request-ID
X-Wp-Cf-Super-Cache-Cookies-Bypass
LB
Yak-Timeinfo
X-Cdn-Cache-Status
Env
X-Mobile-URL
X-Ad-Load-Variation
Cluster
WZWS-RAY
Proxy-Connection
X-Vc
XkeyRZ
X-Location
X-Proxy-CacheRZ
X-CACHE-KEY
CDN
X-VCL-Version
HostName
Srv
X-Aicache-OS
X-Request-Start
X-Edge-Pop
Pramga
On-Server
Ohc-Cache-HIT
X-Cdn-Forward
X-M-Reqid
X-Region-Sid
X-Cache-Tags
X-M-Log
Geoip-Latitude
Ngx
X-Akamai-Pragma-Client-IP
X-Scope-Id
X-NWS-UUID-VERIFY
X-Men
X-Developers
CacheControlHeader
X-Lb-Cache
Server-Id
X-Tim-N
Content-Script-Type
X-Ha-Backend
Content-Style-Type
X-Qnm-Cache
X-Varnish-Beresp-Status
X-Shield-Cache-Expires
X-LB-ID
X-CDN-Cache-Status
X-Wa
X-Via-Popv
X-Cache-FS-Status
X-B3-Trace-ID
X-Nc
X-Acquia-Purge-Cdn-Unconfigured
X-Via-Popn
X-Via-Poph
X-SB
X-Req
X-Minions-Version
X-Servedbyhost
X-V-Cache
X-TX-ID
Tube-Return
V-Age
Click-Count-Error
X-WP-CF-Super-Cache-Cookies-Bypass
Click-Count-Action-Start
CF-Cached-On
Tube-Got-Results
Mime-Version
Tube-Get-Contents
RNT-Time
RNT-Machine
Tube-Got-Eval
X-TT-LOGID
X-Cache-Date
Edge-Cache
X-IN-APIGATEWAYSSL
X-Request-URI
WWW-Authenticate
ENV
X-IN-APIGATEWAY
X-Lb-Nocache
X-Fastly-Country-Code
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-MiniProfiler-Ids
X-Snapshot-Date
X-Dw-Trace-Id
X-Edge-POP
X-Acquia-Purge-Tags
X-Via-Ucdn
PICS-Label
X-Acquia-Site
X-Check-Cacheable
Yjs-Id
X-Cached-Since
Vha6-Origin
X-ElasticPress-Query
X-Miniprofiler-Ids
X-CUA
Inserted-Into-Cache-At
CACHE-MISS-TO-ORIGIN
X-Fastly-Cache-Hits
Log-Origin
Cneonction
X-RAMCache
X-Fastly-Backend-Reqs
X-Iauth-Set-Uid
X-User
X-Litespeed-Cache-Control